{"id":"MAL-2026-12905","summary":"Malicious code in bnpl-blocks-atom-image-gallery (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (629920c8010c4cc8284a3698f4d748214d9ac784f67df8250ace5e656240ecb3)\nOn require() of the package, index.js loads setup.js which reconstructs attacker-controlled hostnames from split-string arrays (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev) with DNS TXT-record fallback via sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. setup.js downloads a platform-specific native executable, writes it to /tmp or the Windows Temp directory under diagnostics-mimicking filenames (dotnet_diag_\u003crand\u003e.exe,.cache_\u003crand\u003e), chmods 0755 on POSIX, and spawns it detached via /bin/sh -c or cmd.exe. Platform-branched payload paths (/pkg/package, /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe) and opt-out env-var checks framed as 'telemetry' provide cover. A second bundled dropper in lib/telemetry.js (81KB) contains identical spawn+chmod+base64-DNS-decode logic with string-concatenated child_process import (require(\"child_\" + \"process\")). The package advertises itself as image gallery components; there is no legitimate reason for such a package to download and execute native binaries at import time.\n","modified":"2026-08-05T15:50:51.786915849Z","published":"2026-08-05T14:51:07Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["35.2.6"],"id":"IN-MAL-2026-015467","import_time":"2026-08-05T15:19:53.045171944Z","modified_time":"2026-08-05T14:51:07Z","sha256":"629920c8010c4cc8284a3698f4d748214d9ac784f67df8250ace5e656240ecb3"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-atom-image-gallery/v/35.2.6"}],"affected":[{"package":{"name":"bnpl-blocks-atom-image-gallery","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-atom-image-gallery"},"versions":["35.2.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"94fef6bca4a2480385b5cb4b8d23bcf388c10cca","sha512_sri":"sha512-XhBzyQT1Y9ZnxKoY+J9/93fJ+q6B79X7j0eoS6QtYOkezRZefz6YrXFowSRMqMZwXwtdSyXsiqSZyjqqrl/v/Q=="},"filename":"bnpl-blocks-atom-image-gallery-35.2.6.tgz"}],"evidence_files":[{"path":"setup.js","sha256":"6834838cab5689a132f208280ccbd7a9597f7874f868ffaa049a4a7171b05015","tlsh":"90b184aa11a770194bb0dbe5c6175415f65af6632380c294fb9ca9881fb7124c3f2efc"},{"sha256":"2d8bb21dda9d5791e2260b025b396bd8b460367172d7f9408157e7da91422390","tlsh":"e7835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc","path":"lib/telemetry.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-atom-image-gallery/MAL-2026-12905.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}